Skip to main content

On the morning of Tuesday 6 October 2026, ASOS customers received a push notification that no retailer wants to send. Headed “ASOS HACKED” and addressed to the company’s data protection officer and IT team, it claimed the company’s Snowflake environment had been compromised and threatened to leak data unless ASOS engaged with the sender. Within hours, screenshots were circulating on social media and ASOS shares had fallen by more than 10%, according to Reuters.

Edward Starkie
Edward Starkie

Director, GRC | Cyber Risk

estarkie@thomasmurray.com

The investigation is ongoing and the picture may look different in a week. But the ASOS breach already carries a clear lesson. The attackers did not need to reach the company’s core systems to create a market-moving event. Access to a third-party customer communications platform was enough.

What happened in the ASOS breach

ASOS confirmed that an unauthorised notification had been sent through one of its customer communication channels and that it had restricted access to the third-party platform involved. In its update to the market, the company said names and contact details may have been accessed, but that it did not believe payment card information or account passwords were affected. The website and app stayed operational throughout.

Responsibility was claimed by a previously unknown group calling itself “Xuanye Group”, which directed recipients to a newly created Telegram channel. Some researchers have cautioned that the name may be a false flag. ASOS, which has around 16.5 million active customers, has not said how many received the notification or how many records may have been accessed. The company told Reuters it holds cyber insurance but that it is too early to quantify any impact on trading.

Snowflake said its investigation was ongoing and that “at this time, we can report that we have found no compromise of the Snowflake platform.” That is reassuring for the thousands of other organisations that rely on it, but it does not settle whether ASOS’s own environment within the service was accessed. ASOS has not named the platform involved or confirmed the route of compromise, and the attackers’ claims of a wider, systemic breach remain unsubstantiated. Commentators have drawn comparisons with the 2024 campaign in which around 165 organisations were exposed through stolen Snowflake customer credentials, but no link has been established.

Why the ASOS hack stands out

UK retail is no stranger to cyber incidents. What sets this one apart is how the pressure was applied. Rather than a ransom note sent quietly to the security team, the attacker used the retailer’s own brand voice to speak directly to its customers.

That changed the shape of the incident. Customers became the audience, the screenshot became the story, and management faced public questions before investigators had established the facts. The fall in the share price is better read as a measure of uncertainty than as an estimate of eventual cost, but it shows how quickly a cyber event becomes a financial one.

There is an uncomfortable irony here. Customer communications platforms are bought to reach large numbers of people quickly, under the company’s name. In the wrong hands, that is exactly what makes them dangerous. Their permissions carry reputational consequences that go well beyond any exposure of personal data.

The Denmark CPR breach: legitimate access, turned against its purpose

A day earlier, Denmark disclosed that the personal details of around 8.8 million people had been taken from its Central Person Register (CPR), the national system behind almost every interaction a Dane has with the state.

According to the CPR, attackers abused a private company’s lawful access to the register to take names, addresses and personal identity numbers. Abnormal activity was seen in September and the breach was identified at the start of October. The CPR has since cut off the company’s access and notified the Danish Data Protection Agency and the police.

No exotic exploit was involved. The access had been legitimately granted to a trusted organisation, and it was used against the system it was meant to serve.

Two breaches, one lesson: your risk lives with your third parties

A global online retailer and a national population register are very different organisations, and these are very different incidents. Both, however, came through a third party. For financial institutions, asset owners and investors, the pattern is familiar: a growing share of cyber and operational risk sits outside your own perimeter, with the suppliers, platforms and partners that hold your data or can act in your name.

Regulators have reached the same conclusion. DORA and NIS2 both put third-party and supply chain risk at the centre of their requirements. In the UK, the Cyber Security and Resilience Bill would extend regulation to managed IT service providers and allow the government to designate critical suppliers.

For investors, the question widens further. Where several portfolio companies depend on the same handful of cloud, SaaS and communications providers, a single compromise can surface in many places at once, and concentration risk in the supply chain becomes concentration risk in the portfolio.

Five questions boards should ask after the ASOS breach

  1. Which third parties hold or can reach our customer data, including marketing, messaging and analytics platforms that may not sit on the core risk register?
  2. Which platforms can publish messages in our name, who holds administrator access, and is that access protected by strong multi-factor authentication?
  3. How is third-party access granted, reviewed and revoked, and would we spot it being used in an unusual way?
  4. Where do our suppliers, or our portfolio companies, depend on the same few providers?
  5. If a supplier were compromised tomorrow, how quickly would we know, and who decides what we tell customers, regulators and the market?

Boards should also rehearse the most uncomfortable version of the scenario in a safe space. A threatening message has gone out under your brand, its claims cannot yet be verified, and customers want answers now. Who can stop further messages? Which channels can safely carry updates? Who approves the wording?

An annual supplier questionnaire captures a single point in time. Threats, access rights and vulnerabilities change weekly. Monitoring for unusual account activity should extend to services that have traditionally sat outside the security team’s scope, and the view of supplier exposure should be continuous rather than periodic.

What ASOS customers should do now

The NCSC advises ASOS customers to assume they could be affected, even if they did not receive the notification. ASOS has asked customers to disregard the message and avoid its external link, and is not currently asking them to change their passwords. Customers should check for updates through independently accessed official channels and stay alert to follow-on scams. A convincing message about compensation or account verification could be the next trap.

The takeaway

Third-party risk is often treated as a procurement and compliance exercise. The ASOS and Denmark breaches show it is also an operational, reputational and market risk, and one that can surface in hours.

Retailers spend years persuading customers to welcome their notifications. Protecting the systems behind that familiar ping deserves the same care as earning the trust that makes people open it. The organisations best placed to respond are not the ones with the longest questionnaires, but those with a continuous, evidence-based view of who they depend on and how exposed those dependencies are.

Cyber Risk

Third Party Cyber Risk

In an era where cyber threats evolve rapidly and third-party risks continue to grow, ensuring the cybersecurity resilience of your business partners and supply chain is more critical than ever. Thomas Murray Cyber helps organisations and investors build a continuous, evidence-based view of third-party cyber exposure with Orbit Diligence, our solution to perform thorough cybersecurity assessments, manage vendor risk, and maintain a secure digital ecosystem.

Learn more

Frequently asked questions

  • What happened in the ASOS breach?

    On 6 October 2026, ASOS customers received an unauthorised push notification headed “ASOS HACKED”, sent through a third-party customer communications platform. ASOS restricted access to the platform and said names and contact details may have been accessed.

  • Was ASOS payment or password data affected?

    ASOS has said it does not believe payment card information or account passwords were affected. The investigation is ongoing.

  • Who was behind the ASOS hack?

    A previously unknown group calling itself Xuanye Group claimed responsibility via a Telegram channel. Its identity has not been independently confirmed.

  • Was Snowflake breached?

    Snowflake said its investigation was ongoing and that it had found no compromise of its platform. The attackers’ wider claims have not been substantiated.

  • What was the Denmark CPR breach?

    Denmark disclosed that the details of around 8.8 million people were taken from its Central Person Register after attackers abused a private company’s lawful access to the system.

  • Why do these breaches matter for third-party risk?

    Both incidents came through a third party rather than a direct attack on core systems. They show that supplier and platform access can create operational, reputational and market consequences within hours, which is why DORA, NIS2 and the UK Cyber Security and Resilience Bill all focus on third-party risk.

Sources

  1. ASOS plc: Update regarding cyber incident, RNS 8604X, 6 October 2026
  2. ITV News: ASOS investigating suspected hack, 6 October 2026
  3. Reuters: ASOS shares slide after hackers target online retailer, 6 October 2026
  4. Reuters: UK online retailer ASOS shares drop on reports of cybersecurity breach, 6 October 2026
  5. BleepingComputer: ASOS confirms data breach after “HACKED” in-app notifications, 6 October 2026
  6. BBC: Snowflake statement on ASOS, reported 7 October 2026
  7. NCSC: Incident affecting ASOS customers, 6 October 2026
  8. NCSC: Incidents impacting retailers: recommendations
  9. NCSC: Data breaches: guidance for individuals and families
  10. Help Net Security: ASOS confirms data breach after hacked app alert reaches shoppers, 7 October 2026
  11. SecurityWeek: ASOS Confirms Cyberattack, Data Breach, 7 October 2026
  12. ASOS Customer Care: Unauthorised ASOS Notification, accessed 7 October 2026
  13. SecurityWeek and The Record: reporting on the Danish CPR breach